Paraphrasing
Summary of Finding From the Lab
The First parts is establishing a remote connection to the Kali virtual machine and then explore the Aircrack-ng suite, a set of WLAN auditing tools, which can be used to compromise WLAN security implementations for each of the hacking application tools such as airman-ng, airodump-ng, aircrack-ng, and aireplay-ng. The second part is providing video that demonstrates the use of these tools in cracking passwords on a WLAN. This video shows how an unencrypted WPA key can be recovered from a weakly protected WLAN. The Third part is use Aircrack-ng to uncover a WPA key on the same capture file (wlan0) in the video. The fourth part is to draft a WLAN security implementation plan to mitigate the risk, threats, and vulnerabilities identified by the lab.
Critical Risks, Threats, and Vulnerabilities on the WLAN
Risks, threats, and vulnerabilities are prominent with WLAN infrastructures such as the eavesdropping, denial of service, man in the middle attack, spoofing, sniffing, and illegal entry in to the network, these are only a few that can occur. There are also risks involved with logging onto access points in airports or other public places, as an attacker can enable a rogue wireless access point to capture credentials and other data while an unsuspecting user connects to the Internet using a free WLAN connection.
Assessment of the Overall Security of This WLAN
Overall security of this WLAN is considered very weak. This required using and utilizing the strong security methods such as encryption, authentication and sitting and configure the firewalls.
Security Recommendations and Conclusion
Below are some of the security countermeasures that must be implemented in order to provide the required security:
· Enabling MAC address filtering on the WAPs. These addresses can be spoofed.
· Disabling SSID broadcast. The SSID can still be found through other means.
· Limiting the amount of available IP host addresses on the WLAN DHCP server to prevent unauthorized DHCP leases.
· Enabling WPA2 to maximize encryption and ensure data transmission confidentiality. WPA2-Enterprise utilizes additional IT infrastructure such as a RADIUS server that helps authenticate and secure against unauthorized access.
· Utilizing hashing for data transmissions and emails through WLANs to ensure data integrity.